Update for OCEAN miners:
Effective 9:00 AM EDT, the default OCEAN stratum endpoint will return to the non-BIP110 chain. Miners on the default endpoint need no action.
Both websites remain live:
Non-BIP110: https://t.co/w5mtvbkyHP
BIP110: https://t.co/yEVkqPyGrw
OCEAN miners have found blocks on both chains since the fork. Every client chooses where their hashrate goes, and that freedom is the bedrock of sovereignty and decentralization.
Your hash. Your choice.
🌊
thank you red team 🚩 for securing public bitcoin infrastructure
it’s been almost an entire week of non-stop hunting for vulnerabilities and disclosures
we’ve seen shit together
some of the most insane shit i’ve ever seen in my life
you’re incredible beings
keep going
“Gray was asking himself for permission, and granting it, in public, to establish that libngu had come to Coldcard as an outside contribution.”
https://t.co/LKQnaJIcbL
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
🚨LOSSES FROM COLDCARD HACK EXCEED $100M
High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.
If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).
More in the thread below 👇
Coldcard Dicerolls: Verification Report
I spent a lot of time today verifying the Coldcard Diceroll seed path in multiple firmware versions. The implementation is correct and can generate up to 256 bits of entropy with 100 dice rolls.
Full report below.
https://t.co/XX5wzMfxG4
COLDCARD FIRMWARE HOTFIX UPDATE CAN BRICK DEVICES
A new bug has been identified in COLDCARD’s emergency firmware hotfix.
While the update fixes the original entropy vulnerability, researchers say a temporary hardware RNG error can leave the device stuck on a fatal error screen before the PIN prompt, preventing users from accessing the upgrade menu.
IMPORTANT UPDATE
WE HAVE CONFIRMATION FUNDS ARE STILL BEING RECOVERED ON NO PASSPHRASE MK3 DEVICES.
THERE IS HOPE FOR RECOVERY IF YOU ACT FAST
MK4S WITH SHORT PASS PHRASES ARE BEING SWEPT
NO ONE IS SAFE ACT NOW
GET YOUR BITCOIN OFF COLD CARDS
URGENT: I’ve seen people saying that they are on vacation and won’t be able to check their coldcard for days until they get back.
If you have one of the affected coldcards and can’t get back in time please call a trusted person, have them go to where your device is stored and walk them through the procedure to transfer funds over FaceTime.
Don’t have a spare key to your house? Have them smash open a window, or kick down a door. I am not joking.
Normally this would obviously be horrible advice but under these circumstances I think it has the potential to save someone’s coins.
Attacks are increasing not decreasing and attackers are starting to crack through the affected mk3’s with pass phrases. There are even credible reports of mk4’s with pass phrases being hit.
You are in a race against motivated and malicious people wanting to steal your wealth.
PLEASE
This is a crazy post. I get it, but we are in crazy times.
If you are in this specific situation, throw the regular rules out the window and do what you must in order to save your coins.
DONT WAIT.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks 960,778 - 960,792 (last ~2.5 hours, still going):
• 218 transactions, 462 victim addresses, 216 fresh destinations.
• 388.92748828 BTC
• EVERY one has ZERO inputs predating the Coldcard firmware boundary
• Rate 13.8 sweeps/block vs 0.3/block in a pre-incident control window = ~45x elevated
• Topology is 1:1 — one fresh destination per victim, only ONE destination received two sweeps. No collector funnel.
• Some funds have already been swept into 2nd hop addresses.
these are LIKELY Coldcard victims -- they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks
MOVE YOUR FUNDS OFF COLDCARD DEVICES ASAP AND USE HIGH TX FEES
more details to come as this takes shape
Bitcoin spent on chain in the last 4 days
Wed/Thurs are what normal days look like. Friday (the hack) and Saturday we see massive old coins on the run especially since 2021.
Heatmap - utxos spent by holding date and BTC amount. Yellow: 1k txs/pixel
Please treat this as urgent. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds.
Help spread the word, especially to people who are less online and may not see this update.
Tldr: miners can prevent theft by disabling RBF as thieves require it when stealing from certain coldcard users.
Doing so requires Knots as Core removed the option to disable RBF in version 29 and 28 is too old for miners to realiastically use.
Having transgenders (people who cant deal with reality) in charge of the most important technology ever made by mankind (Bitcoin) keeps blowing my mind every time I see a retard like @achow101.
Bitcoin Core has no CEO, no board, no formal hierarchy.
But between 2019 and 2025, a small network of developers, funders, and institutions came to control who got in, who got funded, and what got merged.
I am working on a four-article series documenting how informal power over Bitcoin Core was built, exercised, and defended.
Article one scheduled to drop next week.